From nobody Thu Feb 17 13:14:57 2022 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 7CCE819CFB4E; Thu, 17 Feb 2022 13:14:58 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4JzwKZ2r39z3LLx; Thu, 17 Feb 2022 13:14:58 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1645103698; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=9QmohXrRFp2XQd5xFwm9KQV+VCS6/j8FuTBh8RnA/N8=; b=OyXUMxPKzWw2iom4VreAzk5C2GzFzoGj4CnpKw9IVi7lN71+1O/m1VWkicr2GeBjLuyf+0 dLSawQ3cZVaXpjFMz0fLWVc9nf51tGmBy5eue9Cl2pT+hCB69wGcrzwbyJCwBU4lkU4wB1 I1ez/eo0pgs9+RTGgroUt+pP1x+mW6X+nhHihTdX7s53XhQvgRs1WCottoWvS2v6R7VdGd k/HiHHMCi+yNjbE6pHhRLxbKFcZTm6I14seDla08uz4/4XZUrUidMrsj4PY3tNZywLHYJn gLWPRIrFVdAE5aZ9pb+cX9g0Wt6lvyx8fZZV/pcASOPqC1Qq7tzQXJQsrVIsAw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 1DEA1262F; Thu, 17 Feb 2022 13:14:58 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 21HDEwEX007889; Thu, 17 Feb 2022 13:14:58 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 21HDEvJi007888; Thu, 17 Feb 2022 13:14:57 GMT (envelope-from git) Date: Thu, 17 Feb 2022 13:14:57 GMT Message-Id: <202202171314.21HDEvJi007888@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Palle Girgensohn Subject: git: e712bd2191da - main - databases/postgresql-jdbc: update to 42.3.3. List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: girgen X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: e712bd2191da51dfc3830c0119b1a3c1dc4db19d Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1645103698; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=9QmohXrRFp2XQd5xFwm9KQV+VCS6/j8FuTBh8RnA/N8=; b=MUZqNW8shVKHPFlF1AGmqaDZrx/yuqToV1bcFcjnuRBJvLmaNw9asn4h0xLJm+mhJB/sEB wZMv/qZIZWx2V6Do4jdAWDkXV1DZ0VjFNSlyzchSfX8FcQ8Ly4ka5EI0oc1a5AftwlZkVk /yZyO3aA7/ubFynVahOhzDkhYjFR5M/thr3Rq2zE6/ItfCTle1RIpx6UU6Jbi3pB7FAiXQ dIP8Ukq28LlM7GLU9HvjVFRR4oBmLbHIY6P5OKIBhuCMH3x/5N6kaRMAPCUc/u7CgTEjIz 3D8uusAVksjL0UlWWdeddE6j9CvEfARtGQem9hmdsLCct6c+XMEYOy9GQAVojg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1645103698; a=rsa-sha256; cv=none; b=GgHdEGBOME1wQ23CN2Uikb/Za3V5TCPuWy/5DUbiQOv2UqY5JXS4SIITLoly1mp0mQmCdp kgEYSegtaCXmfy7kr0yvK4FQMiD3hOuVOnluPpVvM7k6gGSZWQlEh5kfZIaLGCkCWI4t+D AaRysE0jXkVb3zo06FWdStj9oegzXW43rUmDpGoQ7Ss1bbOtxMdxpfysM7CUe24N6mhZN2 t/FCCQiQnv/zNKyBtkxwQHCF+oAU6d1/Mfy/RUAUJoNmhpmfMF9PGyK/qsH3pJ6tPutbQ8 lCdlS6o0cN78xvU5EQ6dq7akKVXNQArLF4LZvHZhgH/iT0sf5AzST+IZtZIlfw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by girgen: URL: https://cgit.FreeBSD.org/ports/commit/?id=e712bd2191da51dfc3830c0119b1a3c1dc4db19d commit e712bd2191da51dfc3830c0119b1a3c1dc4db19d Author: Palle Girgensohn AuthorDate: 2022-02-17 13:12:12 +0000 Commit: Palle Girgensohn CommitDate: 2022-02-17 13:14:51 +0000 databases/postgresql-jdbc: update to 42.3.3. A security advisory has been created for the PostgreSQL JDBC Driver. The URL connection string loggerFile property could be mis-used to create an arbitrary file on the system that the driver is loaded. Additionally anything in the connection string will be logged and subsequently written into that file. In an insecure system it would be possible to execute this file through a webserver. While we do not consider this a security issue with the driver, we have decided to remove the loggerFile and loggerLevel connection properties in the next release of the driver. Removal of those properties does not make exposing the JDBC URL or connection properties to an attacker safe and we continue to suggest that applications do not allow untrusted users to specify arbitrary connection properties. We are removing them to prevent misuse and their functionality can be delegated to java.util.logging. The changelog is not very useful as the change was done behind a security advisory. The short version is that loggerFile and loggerLevel properties still exist but do not do anything. Security: https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-673j-qm5f-xpv8 --- databases/postgresql-jdbc/Makefile | 2 +- databases/postgresql-jdbc/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/databases/postgresql-jdbc/Makefile b/databases/postgresql-jdbc/Makefile index cfaf2a78928a..f6e08fa6f655 100644 --- a/databases/postgresql-jdbc/Makefile +++ b/databases/postgresql-jdbc/Makefile @@ -1,7 +1,7 @@ # Created by: Palle Girgensohn PORTNAME= postgresql -PORTVERSION= 42.3.1 +PORTVERSION= 42.3.3 CATEGORIES= databases java MASTER_SITES= http://jdbc.postgresql.org/download/ PKGNAMESUFFIX= -jdbc diff --git a/databases/postgresql-jdbc/distinfo b/databases/postgresql-jdbc/distinfo index fc58d3ce4a15..97eedd616464 100644 --- a/databases/postgresql-jdbc/distinfo +++ b/databases/postgresql-jdbc/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1635606114 -SHA256 (postgresql-42.3.1.jar) = 8370570857da86eb4a76dd3d8505d34bac0c18186741fa83a6820a10fa441cb4 -SIZE (postgresql-42.3.1.jar) = 1015689 +TIMESTAMP = 1645102191 +SHA256 (postgresql-42.3.3.jar) = eed0604f512ba44817954de99a07e2a5470aa4bfcb481d4e63a93e0ff0e0aede +SIZE (postgresql-42.3.3.jar) = 1039047